My XP Antivirus 2011 Removal Attempt

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Mcspackle, Jun 20, 2011.

  1. Mcspackle

    Mcspackle Private E-2

    Brief history: I acquired the XP Antivirus 2011 version on June 6th and I tried to remove it by myself. I ran my native AVAST C:/ drive scan and the BIOS scan. I deleted 2 files when AVAST asked what to do with the suspicious files during the BIOS scan and I quarantined then deleted ~ 8 files after I did the C:/ scan.

    This occurred before I found your website so I did not save any logs. After removing the files using AVAST, I could not run any executable programs.

    So, I did a little more searching on the web and found a malware help page which addressed the executable problem, My Antispyware .

    I used Method 1. I could now run executable files, however, my Window Security Alerts "Shield" is red and warns me that I should enable automatic Windows Download. I agree! When I go to the control panel-Automatic Updates- the Automatic Download feature is selected!! - But the icon on the toolbar is red saying the automatic download feature is not engaged. I do not know which one is correct.

    When I go to the Windows website to manually download the most recent updates, I get an error saying

    "The website has encountered a problem and cannot display the page you are trying to view. The options provided below might help you solve the problem.
    For self-help options:

    Frequently Asked Questions

    Find Solutions

    Windows Update Newsgroup
    For assisted support options:

    Microsoft Online Assisted Support (no-cost for Windows Update issues)"

    So, I cannot manually download the XP updates.

    I just would like to know if I am clean and if the Windows update problem is an artifact from the virus.

    Here are the logs - and thank you for taking your valuable time to look over these items.

    If you would like, I have the Malwarebytes log for the June 6th date, when I first ran it. If you need that file, I will repost with that attachment.

    Thanks again,
    Mcspackle
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run Ccleaner to clean out only temp files and nothing else!

    Now make sure these folders have been cleaned out:
    C:\WINDOWS\Temp\
    C:\Documents and Settings\nursing\Local Settings\Temp\

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:

    * C:\Avenger.txt
    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Mcspackle

    Mcspackle Private E-2

    I ran "The Avenger", rebooted and then down loaded CCleaner and ran that. I only checked the "Temporary Internet Files" and the system "Temporary Files" folder.

    When I looked at the
    1) C:\WINDOWS\Temp\ and the
    2) C:\Documents and Settings\nursing\Local Settings\Temp\

    folders, there were many files in both folders. I manually deleted everything in the "C:\Documents and Settings\nursing\Local Settings\Temp\" folder. However, there was a program conflict in the C:\WINDOWS\Temp\ folder when I tried to manually delete all of those folders. An error occrurs saying "spnsrv" is being used by another program and the manual deletion stops. I had no program open, so maybe it was a system file?

    I ran MGtools anyway and uploaded that log in addition to the CCLeaner log.


    I still have the problem with the Red shield indicating my Automatic Updates are not activated even when they are marked green/on in the Control Panel.

    I just noticed an error code on the Microsoft Automatic Download website "[Error number: 0x80070424]". I tried using the Mr Fixit application from Microsoft, but that did not work.

    I rechecked my selection and I only had those two Temp files checked...so I am not sure if I am doing something incorrect.

    Here are the logs.

    Thank you again for your help,

    Mcspackle
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest that you post in the software forum for your issue with the Security center.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds